Privacy Policy
Last updated 8 September 2026. The retention periods below are read from the live configuration, so what this page says is what the system enforces.
What we store
- The temporary addresses we issue, and a one-way hash of every address ever issued, so an address is never reassigned to a different visitor.
- Messages delivered to those addresses: sender, subject, timestamps, the plain-text and sanitised HTML bodies, attachment metadata, and permitted attachment files.
- A browser session identifier that records which inboxes your browser is authorised to open.
- A one-way hash of your IP address for rate limiting and abuse investigation. We do not store your IP address in readable form.
- Administrative audit records of operator actions.
What we do not do
- We do not require or collect a name, a password, or a permanent account.
- We do not send your inbox address, message contents, sender information or recovery secrets to any analytics, advertising, error-reporting or AI service. See Analytics below for exactly what is sent.
- We do not sell personal data.
- We block remote images in messages by default, so simply opening a message does not tell the sender you read it, unless you deliberately choose to load images.
How long we keep things
- An address receives mail for 24 hours by default. You can extend it to 7 days from the inbox screen.
- Stored messages are deleted 24 hours after the address expires. Message bodies, attachments and the raw copy of the message are all destroyed at that point.
- The raw, unprocessed copy of each message is kept for at most 24 hours for troubleshooting, then deleted.
- Browser session records expire on their own and are removed by the same automated jobs.
- The one-way hash of the address is kept permanently so the address is never reissued to someone else; it contains no message content and cannot be reversed.
The inbox screen always shows the two exact times that apply to your address: when it stops receiving, and when its messages are deleted.
Cookies
We set three first-party cookies and nothing else. There is no advertising cookie, no cross-site tracker, and no third-party consent service — the cookie banner on this site is our own code, served from this domain.
tm_gs— the browser session that records which inboxes this browser is allowed to open. Essential: without it your inbox is not yours. Signed, HTTP-only, 30 days.tm_csrf— a token that proves a form submission came from this site. Essential, 24 hours.tb_consent— your cookie choice, so we stop asking. Set only once you choose, 12 months. We also keep a copy in your browser's local storage. Clearing it makes the banner reappear.
If you allow analytics, Google Analytics then sets its own cookies (names beginning _ga) to count returning visits. Until you allow it, Google Consent Mode holds analytics storage in the denied state, so those cookies are not written.
You can change your mind at any time with the Cookie settings link in the footer of every page.
Analytics
We use Google Analytics 4 to count visits and see which pages are used. In the EEA, the UK and Switzerland it stays off unless you accept it; the banner appears for European visitors and analytics is denied by default until you choose. Elsewhere it is on by default and you can turn it off from the same banner. What is sent: the page path (for example /faq), your browser type and screen size, and a truncated IP address. What is never sent: the query string, so no inbox identifier ever leaves the page; message contents; sender addresses; or anything you type. You can block analytics entirely with a content blocker; the site works identically without it.
Backups
Encrypted database backups are taken daily and kept for 14 days, so a message may persist in a backup for that long after it was deleted from the live system. Backups are encrypted, are not readable through the website, and are destroyed on that schedule. We state this rather than claiming instant, total erasure.
Operator access
A small number of named administrators can, in limited circumstances, read the contents of a message: troubleshooting a delivery fault, investigating abuse or security incidents, and complying with a valid legal obligation. Doing so requires a specific permission, a fresh two-factor confirmation and a written reason, and creates a permanent audit record. Ordinary administrative screens show metadata only.
Your choices
You can delete a message or an entire inbox from the interface at any time; deletion destroys the stored body, attachments and raw copy immediately. You can remove an inbox from your browser without deleting it.
Contact
Questions and complaints: abuse@tempbooth.com, or use the Contact & abuse page.